Answered: [Security threat] tags are not sanitized in extra question field

Post date: 2020-07-01 00:44:51
Views: 286

Hey q2apro, I think you are testing the default q_view_extra($q_view); function.

The default function is still safe. But if you pull the content from the databse, it's not safe.

First, look! The script is stored in database.

database

Second, if create a function to pull that content form the datase:

public function q_item_extra($q_item)
{
$postidz = $q_item'raw']'postid'];
$extra = qa_db_read_one_value(qa_db_query_sub(
       'SELECT content FROM ^postmetas WHERE title="qa_q_extra" AND postid=#',
        $postidz
   ), true);
 
 //$extra = $q_item'extra']'content'];
 
        $this->output('My info:'.$extra);   
   
}

Here's the result:

test

I hope you'll get my point.

Please click Here to read the full story.
 
Other Top and Latest Questions:
SpaceX targets $135 IPO price at valuation of $1.77 trillion
Bitcoin's high-conviction holders are turning into sellers as the crypto's price hits new lows
CrowdStrike narrowly beats estimates on AI tailwinds, but stock falls 10%
As Honeywell Aerospace readies for its stand-alone debut, its CEO is forecasting big growth
Best progressive eyeglasses - Warby Parker vs. local optometrist
Bridge Over Troubled Water But Ok Calm Down Not THAT Troubled
Inside Wealth: Soaring stocks created 2 million new millionaires around the world last year
Amazon engineers in Seattle slam employer for building AI data centers while laying off 30,000 staffers
Elon Musk's net worth poised to sail past $1 trillion in SpaceX IPO
Flesh-eating screwworm is confirmed in the U.S., officials say